|
224431
|
5.4 |
MEDIUM
Network
|
fortinet
|
fortisiem
|
An Improper Neutralization of Input vulnerability in the description and title parameters of a Device Maintenance Schedule in FortiSIEM version 5.2.5 and below may allow a remote authenticated attack…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17651
|
2024-11-21 13:32 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224432
|
9.8 |
CRITICAL
Network
|
apache debian canonical fedoraproject redhat
|
xml-rpc debian_linux ubuntu_linux fedora software_collections
|
An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-R…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-17570
|
2024-11-21 13:32 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224433
|
4.7 |
MEDIUM
Local
|
arm fedoraproject debian
|
mbed_tls mbed_crypto fedora debian_linux
|
The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to reco…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2019-18222
|
2024-11-21 13:32 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224434
|
7.5 |
HIGH
Network
|
meinbergglobal
|
syncbox\/ptpv2_firmware
|
The Meinberg SyncBox/PTP/PTPv2 devices have default SSH keys which allow attackers to get root access to the devices. All firmware versions up to v5.34o, v5.34s, v5.32* or 5.34g are affected. The pri…
|
NVD-CWE-noinfo
|
CVE-2019-17584
|
2024-11-21 13:32 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224435
|
6.5 |
MEDIUM
Network
|
cacti
|
cacti
|
Cacti through 1.2.7 is affected by a graphs.php?template_id= SQL injection vulnerability affecting how template identifiers are handled when a string and id composite value are used to identify the t…
|
CWE-89
SQL Injection
|
CVE-2019-17357
|
2024-11-21 13:32 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224436
|
7.8 |
HIGH
Local
|
eclipse
|
memory_analyzer
|
Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a deserialization vulnerability if an index file of a parsed heap dump is replaced by a malicious version and the heap dump is reopened…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2019-17635
|
2024-11-21 13:32 |
2020-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224437
|
9.0 |
CRITICAL
Network
|
eclipse
|
memory_analyzer
|
Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a cross site scripting (XSS) vulnerability when generating an HTML report from a malicious heap dump. The user must chose todownload, o…
|
CWE-79
Cross-site Scripting
|
CVE-2019-17634
|
2024-11-21 13:32 |
2020-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224438
|
9.8 |
CRITICAL
Network
|
saltstack debian opensuse canonical
|
salt debian_linux leap ubuntu_linux
|
In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoin…
|
CWE-77
Command Injection
|
CVE-2019-17361
|
2024-11-21 13:32 |
2020-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224439
|
6.1 |
MEDIUM
Network
|
apache oracle
|
cxf flexcube_private_banking retail_order_broker communications_element_manager communications_session_report_manager communications_session_route_manager commerce_guided_search
|
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which …
|
CWE-79
Cross-site Scripting
|
CVE-2019-17573
|
2024-11-21 13:32 |
2020-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224440
|
5.3 |
MEDIUM
Network
|
linux debian netapp
|
linux_kernel debian_linux a700s_firmware 8300_firmware 8700_firmware a400_firmware h610s_firmware cloud_backup steelstore_cloud_integrated_storage data_availability_service…
|
The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the auto flowlabel of a UDP IPv6 packet rel…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2019-18282
|
2024-11-21 13:32 |
2020-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|